Public · Effective July 21, 2026
Privacy Policy
What data AgenTeach processes, how we protect it, and how schools stay in control. For the engineering-level view, see our Security & Privacy Architecture.
Effective date: July 21, 2026 · Last updated: August 10, 2026 · Contact: privacy@agentea.ch
1. Who we are and what this policy covers
AgenTeach ("we," "us") provides an AI-assisted teacher workspace that helps educators organize student evidence, track follow-ups, and draft family communications. Our service is offered to schools and districts ("LEAs") and their authorized staff. This policy covers the AgenTeach application (portal.agentea.ch), our API (api.agentea.ch), and our marketing site (agentea.ch).
AgenTeach is used by teachers and school staff only. Students do not have accounts, do not log in, and never interact with AgenTeach directly.
2. Our role and student data ownership
When an LEA uses AgenTeach, we act as a school official with a legitimate educational interest under FERPA (34 CFR § 99.31(a)(1)), operating under the LEA's direct control with respect to education records, typically through a signed Data Privacy Agreement (such as the SDPC National Data Privacy Agreement).
All student data belongs to the LEA. We claim no ownership or license beyond what is needed to provide the service. We use student data only for the educational purposes the LEA authorizes — never for advertising, never for profiling, never for sale, and never to train AI models.
3. Data we collect
3.1 Student data (from Google Classroom, teacher entry, or teacher uploads)
| Category | Fields | Source |
|---|---|---|
| Identity | First/last name, school email, external student ID, photo URL | Google Classroom roster sync (teacher-authorized) |
| Enrollment & courses | Course membership, current/previous grade, missing/late work counts | Google Classroom |
| Assignments & submissions | Assignment metadata, submission state, draft/assigned grades, late flags | Google Classroom |
| Guardian contacts | Parent/guardian name, email, relationship, preferred language | Google Classroom / teacher entry |
| Communications | Drafts and records of parent/guardian emails (subject, body, recipients), communication history summaries | Teacher-created (AI-assisted drafting, teacher-reviewed) |
| Teacher observations | Observation notes, evidence summaries and classifications, sensitivity labels | Teacher entry / teacher uploads |
| Attendance context | Attendance events and notes entered by teachers | Teacher entry |
| Parent communication inputs | Text/extracts of communications teachers log (e.g., a note from a parent) | Teacher entry / upload |
3.2 Teacher and staff data
Account identity (name, school email, photo), role and school/district affiliation, timezone and working-hours preferences, and Google/Microsoft OAuth tokens used to connect authorized integrations (stored encrypted — see §7).
3.3 Data we do NOT collect
No student browsing history, no location data, no biometric data, no social media data, no student-facing accounts or chat, no advertising identifiers, and no third-party analytics or tracking cookies anywhere in the application.
4. How we use data
Solely to provide the service the LEA authorizes: syncing rosters and coursework, surfacing follow-ups and alerts for teachers, organizing evidence and observations, and helping teachers draft family communications that they review and send. Aggregated, de-identified data may be used to maintain and improve service reliability; de-identification follows NIST-aligned standards and we commit not to attempt re-identification.
5. AI features
- AI (Google Vertex AI / Gemini, under Google Cloud's enterprise terms) helps draft and extract — e.g., drafting a parent email or extracting facts from a teacher's note. Teachers review every AI draft before anything is sent or saved as a record.
- AI does not make decisions about students (no grading, discipline, eligibility, or diagnostic determinations), and AI output is never auto-sent.
- Student data is never used to train AI models — ours or Google's. Vertex AI is used under terms that exclude training on customer data.
- Where feasible we minimize what AI sees (e.g., email drafting sends first names only). Some features (observation cleanup, communication extraction) process the full text the teacher provides.
- Each AI call is recorded in our audit log (provider, model, purpose — never raw content).
6. Third parties and subprocessors
We share data only with subprocessors necessary to run the service, bound by data protection agreements with confidentiality, security, deletion, and breach-notification obligations. Current subprocessors (see the Subprocessor List for the maintained version):
| Subprocessor | Purpose | Data touched |
|---|---|---|
| Microsoft Azure | Application hosting, database, file storage, transactional email | All service data (encrypted at rest and in transit) |
| Google Cloud (Vertex AI) | AI drafting/extraction | Content of the specific teacher-invoked request |
| Google (Classroom/Workspace APIs) | Roster/coursework sync, sending teacher-approved emails | Data the teacher's OAuth grant covers |
We provide advance notice of subprocessor changes to LEAs under agreement, and any new subprocessor is bound to equivalent terms. We never sell data, never share it for advertising, and never disclose it except as this policy and our LEA agreements describe or as law requires.
7. Security
- TLS 1.2+ encryption in transit everywhere; HSTS on all production hosts.
- Encryption at rest for databases, file storage, and backups; OAuth tokens are additionally application-layer encrypted (Fernet with key rotation).
- Role- and relationship-based access control: every request is checked server-side by district, school, role, and teacher-student relationship.
- Append-only audit logging of sensitive reads, writes, exports, erasures, and AI calls, enforced at the database level.
- Rate limiting, single sign-on via the district's Google or Microsoft identity, and least-privilege OAuth scopes (read-only Classroom access).
- Teacher sign-in uses single sign-on through the district's Google or Microsoft identity provider and therefore inherits the district's multi-factor authentication policy. AgenTeach does not maintain separate passwords for teachers.
8. Data residency
All student data is stored and processed exclusively in United States regions. Application hosting and databases run in Microsoft Azure US regions (Central US), and AI processing runs in Google Cloud Vertex AI's us-central1 (Iowa) region. No student data is stored or processed outside the United States, and our infrastructure configuration pins these regions explicitly rather than relying on provider defaults.
9. Retention and deletion
- We keep student data only while the LEA authorizes the service, plus the retention windows in our published Data Retention & Deletion Schedule (e.g., unsent draft emails ≤ 365 days, resolved alerts ≤ 180 days). Windows are LEA-configurable, and automated purging enforces them.
- On LEA request or contract termination, student data is exported (if requested) and deleted within 60 days, consistent with NDPA § 4.6 and Texas Education Code § 32.156. Legal holds and correction-record obligations can defer specific records, and deletion propagates to backups on the backup rotation cycle — we never promise instantaneous eradication from every backup medium, and we say so honestly.
- Parents and eligible students exercise access/correction/deletion rights through their LEA; we support LEA requests within 30 days.
11. Children's privacy (COPPA)
AgenTeach is teacher-facing; children under 13 never use it directly. Where student records include data about children under 13, we process it solely for the school's educational purposes under the school-consent framework, with the protections in this policy (no ads, no profiling, no sale, no AI training, published retention limits, written security program). If we add any student-facing features, we will implement full COPPA notice and consent controls first.
12. Breach notification
We maintain a written incident response plan. If a breach affects student data, we notify affected LEAs without unreasonable delay and within the timelines our agreements and applicable law require (72 hours under NDPA v2.2, and Texas Business & Commerce Code § 521.053 timelines for Texas individuals/AG where applicable), including the nature of the breach, data involved, steps taken, and contact information.
13. Changes to this policy
We post changes here with an updated effective date and a changelog, and we notify LEA contacts and account holders (email or in-app) in advance of material changes.
Change log
v1.2 (2026-08-10) — corrected the §10 description of how session cookies work across our subdomains (the prior text misstated the technical reason). Cookie attributes, data practices, and every commitment are unchanged.
v1.1 (2026-07-27) — the retention schedule referenced in §9 is now published at /retention; §9 links to it directly. No substantive change to any commitment.
v1.0 (2026-07-21) — first published version. Supersedes the trust-page-only posture (the prior architecture overview now lives at /security); residency commitment verified against infrastructure (US-only, §8); MFA wording states the SSO-inherited model plainly (§7).
14. Contact
AgenTeach LLC, a Delaware limited liability company
privacy@agentea.ch